|
[x]
Posted via EE Mobile
|
||
Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again. |
||
| Question |
|
[x]
Attachment Details
|
||
|
[x]
The Solution Rating System
|
||
With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.
Your Input Matters If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support. Thank you! |
||
1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: 30: 31: 32: 33: 34: 35: 36: 37: 38: 39: 40: 41: 42: 43: 44: 45: 46: 47: 48: 49: 50: 51: 52: 53: 54: 55: 56: 57: 58: 59: 60: 61: 62: 63: 64: 65: 66: 67: 68: 69: 70: 71: 72: 73: 74: 75: 76: 77: 78: 79: 80: 81: 82: 83: 84: 85: 86: 87: 88: 89: 90: 91: 92: 93: 94: 95: 96: 97: 98: 99: 100: 101: 102: 103: 104: 105: 106: 107: 108: 109: 110: 111: 112: 113: 114: 115: 116: 117: 118: 119: 120: 121: 122: 123: 124: 125: 126: 127: 128: 129: 130: 131: 132: 133: 134: 135: 136: 137: 138: 139: 140: 141: 142: 143: 144: 145: 146: 147: 148: 149: 150: 151: 152: 153: 154: 155: 156: 157: 158: 159: 160: 161: 162: 163: 164: 165: 166: 167: 168: 169: 170: 171: 172: 173: 174: 175: 176: 177: 178: 179: 180: 181: 182: 183: 184: 185: 186: 187: 188: 189: 190: 191: 192: 193: 194: 195: 196: 197: 198: 199: 200: 201: 202: 203: 204: 205: 206: 207: 208: 209: 210: 211: 212: 213: 214: 215: 216: 217: 218: 219: 220: 221: 222: 223: 224: 225: 226: 227: 228: 229: 230: |
ASA Version 7.2(4) ! hostname BIGFW domain-name dns.xxxxxx.com enable password xxxxxx encrypted passwd xxxxxx encrypted dns-guard ! interface Ethernet0/0 nameif Outside security-level 0 ip address Outside_ASA_5510 255.255.255.0 ! interface Ethernet0/1 nameif Dmz security-level 50 ip address 172.16.1.1 255.255.255.0 ! interface Ethernet0/2 nameif Inside security-level 100 ip address 192.168.1.1 255.255.255.0 ! interface Ethernet0/3 shutdown no nameif no security-level no ip address ! interface Management0/0 nameif management security-level 100 ip address 192.168.2.1 255.255.255.0 management-only ! banner exec Welcome to the BI Group ASDM! Unauthorized access to this device is strictly forbidden. banner login Welcome to the BI Group ASDM! Unauthorized access to this device is strictly forbidden. banner asdm Welcome to the BI Group ASDM! Unauthorized access to this device is strictly forbidden. boot system disk0:/asa724-k8.bin ftp mode passive clock timezone PST -8 clock summer-time PDT recurring dns server-group DefaultDNS domain-name dns.trustbigroup.com object-group service WebAccess tcp port-object eq www object-group service SQLAccess tcp port-object eq 1433 object-group service TSAccess tcp port-object eq 3389 object-group service SecureWebAccess tcp port-object eq https object-group network DM_INLINE_NETWORK_1 network-object host Inside_Landmark_SQL network-object host Inside_Internet_SQL object-group service MerakWebAccess tcp port-object eq 32000 port-object eq 32001 object-group network Internet_SAI_CRS network-object host SAI_CRS_1 network-object host SAI_CRS_2 network-object host SAI_CRS_3 network-object host SAI_CRS_4 object-group service DM_INLINE_TCP_1 tcp group-object WebAccess port-object eq https object-group protocol TCPUDP protocol-object udp protocol-object tcp object-group service DM_INLINE_TCP_2 tcp group-object WebAccess port-object eq https object-group network Internet_ICE network-object host ICE_1 object-group network NTP_Servers_Outside network-object host NTP_Server_3 network-object host NTP_Server_4 network-object host NTP_Server_5 network-object host NTP_Server_1 network-object host NTP_Server_2 object-group network DM_INLINE_NETWORK_4 network-object host Outside_BI network-object host Outside_OCS access-list Dmz_access_in extended permit udp 172.16.1.0 255.255.255.0 host 10.1.1.1 eq ntp access-list Dmz_access_in remark Name resolution for any server on the Dmz access-list Dmz_access_in extended permit object-group TCPUDP 172.16.1.0 255.255.255.0 any eq domain access-list Dmz_access_in remark Web access for any server on the Dmz access-list Dmz_access_in extended permit tcp 172.16.1.0 255.255.255.0 any object-group DM_INLINE_TCP_2 access-list Dmz_access_in remark SAI Webservice ==> TU ACE System access-list Dmz_access_in extended permit ip host Dmz_Webservices host TUNA inactive access-list Dmz_access_in remark Mail access to inside mail server access-list Dmz_access_in extended permit tcp 172.16.1.0 255.255.255.0 host Inside_MailSvr eq smtp access-list Dmz_access_in remark Soap access to the MessageSvr access-list Dmz_access_in extended permit tcp 172.16.1.0 255.255.255.0 host Inside_MessageSvr object-group WebAccess access-list Dmz_access_in remark SQL access to all internal SQL servers access-list Dmz_access_in extended permit tcp 172.16.1.0 255.255.255.0 object-group DM_INLINE_NETWORK_1 object-group SQLAccess access-list Outside_access_in extended permit tcp object-group Internet_SAI_CRS host Outside_Webservices eq https access-list Outside_access_in extended permit tcp host Internet_XXXXXX host Outside_Mail eq pop3 access-list Outside_access_in extended permit tcp any host Outside_Mail eq smtp access-list Outside_access_in extended permit tcp any object-group DM_INLINE_NETWORK_4 object-group DM_INLINE_TCP_1 access-list BIGroupVPN_splitTunnelAcl standard permit 192.168.1.0 255.255.255.0 access-list Inside_nat0_outbound remark VPN NAT access-list Inside_nat0_outbound extended permit ip 192.168.1.0 255.255.255.0 VPN-network 255.255.255.0 access-list csc extended permit tcp any any eq smtp access-list csc extended deny tcp host 192.168.1.2 any eq www access-list csc extended permit tcp any any eq www pager lines 24 logging enable logging timestamp logging trap informational logging asdm notifications logging mail notifications logging facility 17 logging device-id hostname logging host Inside 192.168.1.195 logging rate-limit 1 60 level 2 mtu Outside 1500 mtu Dmz 1500 mtu Inside 1500 mtu management 1500 ip local pool BIGroup_VPN_IP_Pool 192.168.3.1-192.168.3.254 mask 255.255.255.0 ip verify reverse-path interface Outside ip verify reverse-path interface Dmz icmp unreachable rate-limit 1 burst-size 1 asdm image disk0:/asdm-524.bin asdm history enable arp timeout 14400 nat-control global (Outside) 1 interface global (Dmz) 1 interface nat (Dmz) 1 172.16.1.0 255.255.255.0 nat (Inside) 0 access-list Inside_nat0_outbound nat (Inside) 1 192.168.1.0 255.255.255.0 static (Dmz,Inside) Dmz_Websvr Dmz_Websvr netmask 255.255.255.255 static (Dmz,Outside) Outside_BI Dmz_BI netmask 255.255.255.255 dns static (Dmz,Inside) Dmz_BI Dmz_BI netmask 255.255.255.255 static (Dmz,Outside) Outside_OCS Dmz_OCS netmask 255.255.255.255 static (Dmz,Inside) Dmz_OCS Dmz_OCS netmask 255.255.255.255 static (Dmz,Outside) Outside_Webservices Dmz_Webservices netmask 255.255.255.255 dns static (Inside,Dmz) Inside_Internet_SQL Inside_Internet_SQL netmask 255.255.255.255 static (Inside,Dmz) Inside_MessageSvr Inside_MessageSvr netmask 255.255.255.255 static (Inside,Dmz) Inside_Landmark_SQL Inside_Landmark_SQL netmask 255.255.255.255 static (Dmz,Inside) Dmz_Webservices Dmz_Webservices netmask 255.255.255.255 dns static (Inside,Dmz) Inside_MailSvr Inside_MailSvr netmask 255.255.255.255 static (Inside,Outside) Outside_Mail Inside_MailSvr netmask 255.255.255.255 access-group Outside_access_in in interface Outside access-group Dmz_access_in in interface Dmz route Outside 0.0.0.0 0.0.0.0 10.1.1.1 1 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00 timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute http server enable http VPN-network 255.255.255.0 Inside http 192.168.2.0 255.255.255.0 Inside http 192.168.1.0 255.255.255.0 Inside no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac crypto dynamic-map Outside_dyn_map 20 set pfs group1 crypto dynamic-map Outside_dyn_map 20 set transform-set ESP-3DES-SHA crypto map Outside_map 65535 ipsec-isakmp dynamic Outside_dyn_map crypto map Outside_map interface Outside crypto isakmp enable Outside crypto isakmp policy 10 authentication pre-share encryption 3des hash sha group 2 lifetime 86400 telnet 0.0.0.0 0.0.0.0 Inside telnet timeout 5 ssh timeout 5 console timeout 0 management-access Inside dhcpd address 192.168.2.2-192.168.2.254 management ! ntp server 10.1.1.1 group-policy BIGroupVPN internal group-policy BIGroupVPN attributes wins-server value 192.168.1.185 dns-server value 192.168.1.185 vpn-tunnel-protocol IPSec split-tunnel-policy tunnelspecified split-tunnel-network-list value BIGroupVPN_splitTunnelAcl default-domain value biinc.com username xxxxxxx password xxxxxx encrypted username xxxxxx attributes vpn-group-policy BIGroupVPN tunnel-group BIGroupVPN type ipsec-ra tunnel-group BIGroupVPN general-attributes address-pool BIGroup_VPN_IP_Pool default-group-policy BIGroupVPN tunnel-group BIGroupVPN ipsec-attributes pre-shared-key * ! class-map inspection_default match default-inspection-traffic class-map csc match access-list csc ! ! policy-map type inspect dns migrated_dns_map_1 parameters message-length maximum 512 policy-map global_policy class inspection_default inspect dns migrated_dns_map_1 inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect esmtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp ! service-policy global_policy global smtp-server 192.168.1.6 prompt hostname context Cryptochecksum:8d7d8e5d175da6fsdg487tgfb53fb357c532 : end |
Advertisement
| Hall of Fame |